CVE-2019-9511
HIGHHTTP/2 - DoS
Title source: llmDescription
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
Exploits (1)
References (47)
... and 27 more
Scores
CVSS v3
7.5
EPSS
0.1513
EPSS Percentile
94.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-770
CWE-400
Status
published
Affected Products (28)
apple/swiftnio
< 1.4.0
apache/traffic_server
< 6.2.3
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux
synology/skynas
synology/diskstation_manager
synology/vs960hd_firmware
fedoraproject/fedora
fedoraproject/fedora
opensuse/leap
opensuse/leap
redhat/jboss_core_services
... and 13 more
Timeline
Published
Aug 13, 2019
Tracked Since
Feb 18, 2026